Lucene search

K
wpexploitLana CodesWPEX-ID:5B1AACD1-3F75-4A6F-8146-CBB98A713724
HistoryFeb 09, 2023 - 12:00 a.m.

Scriptless Social Sharing < 3.2.2 - Contributor+ Stored XSS

2023-02-0900:00:00
Lana Codes
142
scriptless social sharing
gutenberg block
stored xss
advanced option
exploit
previewing post

EPSS

0.001

Percentile

23.3%

The plugin does not validate and escape some of its block options before outputting them back in a page/post where the block is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.

Add a "Scriptless Social Sharing" Gutenberg block to a post and put the following payload in the "Additional CSS class(es)" advanced block option:

" onmouseover="alert(/XSS/)" style="background:red;"

The XSS will be triggered when previewing/viewing the post and moving the mouse over the red block

EPSS

0.001

Percentile

23.3%

Related for WPEX-ID:5B1AACD1-3F75-4A6F-8146-CBB98A713724